Privacy Policy

Last updated: June 2026

ShipProof helps you scan your apps for security and DevOps issues. This page explains what we collect, what we don't, and how you stay in control of your data.

What we collect

When you use ShipProof, we store:

  • Your email address (from GitHub sign-in)
  • Your GitHub username
  • Scan results — issue names, severity, fix prompts, and scores
  • Which repo you scanned and when

What we don't collect

We do not store your source code. Files are fetched from GitHub only during a scan, analyzed in memory, and discarded. We never save a copy of your codebase.

How we use your data

We use your information only to run ShipProof — sign you in, run scans, show your reports, and save your scan history. We don't sell your data or use it for advertising.

Third-party services

ShipProof relies on these providers to operate:

  • Supabase — authentication and database
  • Vercel — hosting
  • Anthropic — AI-powered code analysis during scans
  • GitHub — sign-in and read-only repo access for scanning

Each provider has its own privacy policy. We only share the minimum data needed for the service to work.

Data retention

We keep your account and scan history until you delete them. If you delete your account, your data is removed from our systems.

Delete your data

You can delete individual scans from your dashboard at any time. To remove your entire account and all associated data, use the delete option in settings (one click).

Contact

Questions about privacy? Email us at privacy@shipproof.app.

See also our Terms of Service.